In a chilling reminder of the ongoing cat-and-mouse game between AI system developers and security researchers, recent revelations have exposed a new dimension of vulnerability in large language models (LLMs) like ChatGPT—one that hinges not on sophisticated technical exploits, but on the clever...
adversarial attacks
adversarial prompts
ai in cybersecurity
ai red teaming
ai regulation
ai safety filters
ai security
ai vulnerabilities
chatgpt safety
conversational ai
llm safety
product key
prompt
prompt engineering
prompt obfuscation
securityresearcher
social engineering
threat detection
At just 13 years old, Dylan has emerged as a formidable force in the cybersecurity realm, collaborating with the Microsoft Security Response Center (MSRC) to identify and rectify vulnerabilities across Microsoft's vast array of products. His journey from a curious student to a recognized...
A critical and as yet unpatched vulnerability in Windows Server 2025 has shaken the enterprise security community, exposing devastating privilege escalation risks for nearly any Active Directory (AD) environment leveraging the platform. Security researchers at Akamai uncovered the exploit—dubbed...
active directory
active directory attack
ad permissions
attribute manipulation
cyberattack prevention
cybersecurity
dmsa vulnerability
domain controller
domain controller security
enterprise security
incident response
kerberos attacks
microsoft
microsoft patch
microsoft security
microsoft vulnerabilities
network security
operational security
permission management
privilege escalation
securitysecurity advisory
security best practices
security mitigation
securityresearchersecurity risks
server security
threat detection
vulnerability
vulnerability disclosure
windows server
windows server 2025
Microsoft’s recent Windows update released in April 2025 has introduced an unexpected and somewhat controversial element to the Windows file system: an empty folder named "inetpub" appearing on many user systems. This update, part of Windows 11 24H2 and Windows 10 cumulative patches (notably...
cve-2025-21204
directory hijacking
directory junctions
file security
iis
inetpub folder
it administration
it security news
microsoft patch
mklink
patch management
securitysecurity alert
security best practices
security patch
securityresearchersecurity updates
symlink exploits
system administration
system files
system folder security
update risks
vulnerability
windows 10
windows 11
windows 2025
windows activation
windows security
windows update
windows vulnerabilities
Here is a summary of the original Petri article on the Windows 11 'inetpub' folder security risk:
What happened?
After the April 2025 Patch Tuesday update, a new "inetpub" folder started appearing on Windows 10 and 11 machines.
Microsoft created this folder to help patch a bug (CVE-2025-21204)...
administrative permissions
cve-2025-21204
cyberattack prevention
cybersecurity
cybersecurity best practices
directory junctions
endpoint security
extended security updates
file security
folder permissions
iis
inetpub folder
insider threats
it admin tips
itprotection
junction points
local exploit
malware
malware risks
microsoft
microsoft april 2025 update
microsoft patch
microsoft security
os security
patch management
permission hardening
permissions
securitysecurity alert
security mitigation
security patch
securityresearchersecurity updates
security workaround
symbolic link exploit
symbolic links
symlink exploits
symlinks
sysadmin tips
system administration
system integrity
system protection
system update bypass
update management
vulnerabilities
vulnerability
windows 10
windows 11
windows defender
windows security
windows servicing
windows system folder
windows system risks
windows update
windows update risks
windows vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) recently unveiled its Vulnerability Disclosure Policy (VDP) Platform 2023 Annual Report, showcasing its significant achievements during its second full year of operation. With cybersecurity threats continuously evolving, the report...
At Black Hat USA each year, we unveil the Top 100 Security Researcher list to reflect the amazing engagement we get from the community. During this period, we had several thousand researchers engage with the Microsoft Security Response Center (MSRC). We appreciate all the partnership and...
2016
acknowledgements
annual report
blackhat usa
bounty for defense
community engagement
cybersecurity
industry collaboration
microsoft
mitigation bounty
msrc
research
research impact
research methodologies
research recognition
securityresearchersecurity risks
severity rating
top 100
vulnerabilities
Criminal Hacker "Iceman" gets 13 years. Former "Security Researcher- Max Butler" has been sentenced to 13 years for hacking into a financial institutions and stealing credit card account numbers.